# Security policy ## Supported versions Security fixes go to the newest release and to the `development` branch. Older releases do not receive them. ## Reporting a vulnerability **Do not open a public issue for a security problem.** A public report tells everyone about the flaw before there is a fix. Report it privately to **opensource@petrbalvin.org**. Include: - the version or commit you tested, and the platform - what the problem is, and what an attacker gains from it - the smallest reproducer you have, ideally a test or a single command - a suggested fix, if you have one ## What to expect - A human reads the report, and you get an acknowledgement. - You are kept informed while the fix is being made, and told when it ships. - The fix is released before the details are published, and the timing is agreed with you. - The reporter is credited in the release notes, unless anonymity is requested. ## Out of scope - Findings that require the attacker to already run code on the server host, or to hold local access to it. - Missing hardening with no demonstrated impact.